jpfulton
asked on
RegCleanPro, Delta-Search, BitGuard -- Tried to remove... no luck
Hi. Working on a computer for a friend. I'm not sure if it's really full on virus/trojan/malware or if it's just really difficult to remove. All I've done so far is run HitmanPro twice. It found a lot of stuff and removed it the first time. About 9 entries were trojans/riskware/etc. The second time I ran it, it found only one virus (BitGuard.dll). The computer is UNBELIEVABLY slow and it shouldn't be based on it's specs. I used it a few months ago and it's performance was normal. Here's my DDS log to get started. Please let me know what's next. THANK YOU!!
DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 10.0.9200.16686 Â BrowserJavaVersion: 10.25.2
Run by Owner at 14:25:53 on 2013-09-19
Microsoft Windows 7 Professional  6.1.7601.1.1252.1.1033.18. 3932.3305 [GMT -4:00]
.
AV: Microsoft Security Essentials Prerelease *Enabled/Updated* {641105E6-77ED-3F35-A304-7 65193BCB75 F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-D A132C1ACF4 6}
SP: Microsoft Security Essentials Prerelease *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4 D23E83BFDE 2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.ex e
C:\Windows\system32\svchos t.exe -k DcomLaunch
C:\Windows\system32\svchos t.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchos t.exe -k LocalServiceNetworkRestric ted
C:\Windows\system32\svchos t.exe -k netsvcs
C:\Windows\system32\svchos t.exe -k LocalService
C:\Windows\system32\svchos t.exe -k NetworkService
C:\Windows\system32\svchos t.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon .exe
C:\Windows\System32\svchos t.exe -k LocalSystemNetworkRestrict ed
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\system properties remote.exe
C:\Windows\system32\taskmg r.exe
C:\Windows\system32\wbem\w miprvse.ex e
C:\Windows\System32\cscrip t.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uURLSearchHooks: UrlSearchHook Class: {00000000-6E41-4FD3-8538-5 02F5495E5F C} - C:\Program Files (x86)\Ask.com\GenericAskTo olbar.dll
mWinlogon: Userinit = userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D 4DAF1D92D4 3} - C:\Program Files (x86)\Java\jre7\bin\ssv.dl l
BHO: TidyNetwork.com: {7736C7FA-512D-11E2-B871-D EC36088709 B} - C:\Users\Owner\AppData\Loc al\TidyNet work.com\t idy2ie.dll
BHO: Define: {B78F92C8-DEB3-11E2-9A0A-F B64281D6AD E} - C:\Users\Owner\AppData\Loc al\DefineE xt\temp.da t
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4 243D812744 0} - C:\Program Files (x86)\Ask.com\GenericAskTo olbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9 C25C1C588A 9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv .dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4 243D812744 0} - C:\Program Files (x86)\Ask.com\GenericAskTo olbar.dll
TB: Delta Toolbar: {82E1477C-B154-48D3-9891-3 3D83C26BCD 3} - C:\Program Files (x86)\Delta\delta\1.8.24.6 \deltaTlbr .dll
mRun: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
mRun: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSy ncManager. exe  startup
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeA RM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windo ws\STARTM~ 1\Programs \Startup\Q UICKB~1.LN K - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QB Update\qbu pdate.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\OFFIC E11\EXCEL. EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3 C9C571A826 3} - {FF059E31-CC5A-4E2E-BF3B-9 6E929D6550 3}
DPF: {D27CDB6E-AE6D-11CF-96B8-4 4455354000 0} - hxxp://fpdownload2.macrome dia.com/ge t/shockwav e/cabs/fla sh/swflash .cab
TCP: NameServer = 10.0.0.2
TCP: Interfaces\{F1AAC217-E342- 4BCD-B559- 3BFB63A2AA EC} : DHCPNameServer = 10.0.0.2
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-8 6486D72E74 9} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggablePro tocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-5 3150405FD5 7} -
AppInit_DLLs= c:\progra~3\bitguard\26167 3~1.238\{c 16c1~1\bit guard.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A 69D9E530F9 6} - "C:\Program Files (x86)\Google\Chrome\Applic ation\29.0 .1547.66\I nstaller\c hrmstp.exe " --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-Run: [picon] "C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PIconStartup.exe" -startup
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-8 6486D72E74 9} - <orphaned>
x64-Handler: qbwc - {FC598A64-626C-4447-85B8-5 3150405FD5 7} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Owner\AppData\Roa ming\Mozil la\Firefox \Profiles\ ditm8wqa.d efault\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ ResultsExt .aspx?ctid =CT3309350 &CUI=UN248 2287898814 3265&UM=2& SearchSour ce=3&q={se archTerms}
FF - prefs.js: browser.search.selectedEng ine -
FF - prefs.js: browser.startup.homepage - hxxp://www2.delta-search.c om/?babsrc =HP_ss&mnt rId=C02C00 24E820B956 &affID=122 786&tt=110 913_221&ts p=5002
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ ResultsExt .aspx?ctid =CT3309350 &SearchSou rce=2&CUI= UN24822878 988143265& UM=2&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dl l
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21 .153\npGoo gleUpdate3 .dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin 2\npjp2.dl l
FF - plugin: C:\Windows\SysWOW64\Macrom ed\Flash\N PSWF32_11_ 8_800_168. dll
FF - plugin: C:\Windows\SysWOW64\npDepl oyJava1.dl l
FF - plugin: C:\Windows\SysWOW64\npmpro xy.dll
FF - ExtSQL: 2013-09-03 00:00; umylsm@sqhjcpzmeselzlp.org ; C:\Users\Owner\AppData\Roa ming\Mozil la\Firefox \Profiles\ ditm8wqa.d efault\ext ensions\um ylsm@sqhjc pzmeselzlp .org
FF - ExtSQL: 2013-09-03 15:51; tidynetwork@tidynetwork; C:\Users\Owner\AppData\Roa ming\Mozil la\Firefox \Profiles\ ditm8wqa.d efault\ext ensions\ti dynetwork@ tidynetwor k
FF - ExtSQL: 2013-09-03 15:52; {650598e1-b35a-45d3-b607-8 96d7acb64c 3}; C:\Users\Owner\AppData\Roa ming\Mozil la\Firefox \Profiles\ ditm8wqa.d efault\ext ensions\{6 50598e1-b3 5a-45d3-b6 07-896d7ac b64c3}
FF - ExtSQL: 2013-09-11 15:49; ffxtlbr@delta.com; C:\Users\Owner\AppData\Roa ming\Mozil la\Firefox \Profiles\ ditm8wqa.d efault\ext ensions\ff xtlbr@delt a.com
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.delta.tlbrSrchU rl -
FF - user.js: extensions.delta.id - c02c4b1b0000000000000024e8 20b956
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0 EDE6CF018F 3}
FF - user.js: extensions.delta.instlDay - 15959
FF - user.js: extensions.delta.vrsn - 1.8.24.6
FF - user.js: extensions.delta.vrsni - 1.8.24.6
FF - user.js: extensions.delta.vrsnTs - 1.8.24.615:49:40
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlR st - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrac k - affID=122786&tt=110913_221 &tsp=5002
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\driv ers\e1k60x 64.sys [2009-6-10 220672]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\Syste m32\driver s\HECIx64. sys [2012-9-17 56344]
S0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32 \drivers\M pFilter.sy s [2013-8-28 250352]
S2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32 \drivers\N isDrvWFP.s ys [2013-1-20 139616]
S3 dmvsc;dmvsc;C:\Windows\Sys tem32\driv ers\dmvsc. sys [2010-11-21 71168]
S3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32 \drivers\h itmanpro37 .sys [2013-9-19 32512]
S3 MBAMProtector;MBAMProtecto r;C:\Windo ws\System3 2\drivers\ mbam.sys [2013-9-18 25928]
S3 TsUsbFlt;TsUsbFlt;C:\Windo ws\System3 2\drivers\ TsUsbFlt.s ys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32 \drivers\T sUsbGD.sys [2010-11-20 31232]
.
=============== Created Last 30 ================
.
2013-09-19 17:50:24 Â Â Â Â Â 32512 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver s\hitmanpr o37.sys
2013-09-18 22:35:44 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa ming\Malwa rebytes
2013-09-18 22:35:16 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\Malwarebyte s
2013-09-18 22:35:08 Â Â Â Â Â 25928 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver s\mbam.sys
2013-09-18 22:35:07 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-18 22:34:50 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc al\Program s
2013-09-18 22:32:09 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Windows\pss
2013-09-18 21:21:17 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\HitmanPro
2013-09-18 17:18:50 Â Â Â Â Â 9694160 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\ProgramData\Microsoft\M icrosoft Antimalware\Definition Updates\{C4E423AC-3C49-438 E-99E9-306 C76CB2E91} \mpengine. dll
2013-09-16 17:22:12 Â Â Â Â Â 9694160 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\ProgramData\Microsoft\M icrosoft Antimalware\Definition Updates\Backup\mpengine.dl l
2013-09-14 23:34:24 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\BitGuard
2013-09-12 15:50:48 Â Â Â Â Â 155584 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver s\ataport. sys
2013-09-12 15:47:19 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc al\avgchro me
2013-09-12 15:38:12 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\Systweak
2013-09-12 15:38:09 Â Â Â Â Â 16896 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\sasnat ive64.exe
2013-09-12 15:38:09 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\Advanced System Protector
2013-09-11 19:49:40 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa ming\Systw eak
2013-09-11 19:49:38 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\Delta
2013-09-11 19:49:37 Â Â Â Â Â 19368 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\roboot 64.exe
2013-09-11 19:49:33 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa ming\Delta
2013-09-11 19:49:29 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\RegClean Pro
2013-09-11 19:49:02 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa ming\BabSo lution
2013-09-11 19:49:02 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\DSearchLink
2013-09-11 19:48:46 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\Babylon
2013-09-07 18:13:45 Â Â Â Â Â 965008 Â Â Â Â Â ------w- Â Â Â Â Â C:\ProgramData\Microsoft\M icrosoft Antimalware\Definition Updates\{7DF6B888-BCA6-490 6-B175-20A 332AF1717} \gapaengin e.dll
2013-09-03 19:52:11 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc al\Weather Bug
2013-09-03 19:52:10 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa ming\Weath erBug
2013-09-03 19:52:08 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\AWS
2013-09-03 19:51:25 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc al\DefineE xt
2013-09-03 19:51:17 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc al\TidyNet work.com
2013-08-28 20:35:00 Â Â Â Â Â 250352 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver s\MpFilter .sys
.
==================== Find3M Â ====================
.
2013-09-19 17:43:33 Â Â Â Â Â 71048 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\FlashP layerCPLAp p.cpl
2013-09-19 17:43:33 Â Â Â Â Â 692616 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\FlashP layerApp.e xe
2013-08-28 20:35:02 Â Â Â Â Â 139616 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver s\NisDrvWF P.sys
2013-08-10 05:22:18 Â Â Â Â Â 2241024 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\winine t.dll
2013-08-10 05:20:59 Â Â Â Â Â 3959296 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\jscrip t9.dll
2013-08-10 05:20:55 Â Â Â Â Â 67072 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\iesetu p.dll
2013-08-10 05:20:55 Â Â Â Â Â 136704 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\iesysp rep.dll
2013-08-10 03:59:10 Â Â Â Â Â 1767936 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\winine t.dll
2013-08-10 03:58:09 Â Â Â Â Â 2876928 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\jscrip t9.dll
2013-08-10 03:58:06 Â Â Â Â Â 61440 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\iesetu p.dll
2013-08-10 03:58:06 Â Â Â Â Â 109056 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\iesysp rep.dll
2013-08-10 03:17:38 Â Â Â Â Â 2706432 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\mshtml .tlb
2013-08-10 03:07:50 Â Â Â Â Â 2706432 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\mshtml .tlb
2013-08-10 02:27:59 Â Â Â Â Â 89600 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\Regist erIEPKEYs. exe
2013-08-10 02:17:19 Â Â Â Â Â 71680 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\Regist erIEPKEYs. exe
2013-08-08 01:20:43 Â Â Â Â Â 3155456 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\win32k .sys
2013-08-02 02:23:53 Â Â Â Â Â 5550528 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\ntoskr nl.exe
2013-08-02 02:15:44 Â Â Â Â Â 1732032 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\ntdll. dll
2013-08-02 02:15:03 Â Â Â Â Â 362496 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\wow64w in.dll
2013-08-02 02:15:03 Â Â Â Â Â 243712 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\wow64. dll
2013-08-02 02:15:03 Â Â Â Â Â 13312 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\wow64c pu.dll
2013-08-02 02:14:57 Â Â Â Â Â 215040 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\winsrv .dll
2013-08-02 02:14:11 Â Â Â Â Â 16384 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\ntvdm6 4.dll
2013-08-02 02:13:34 Â Â Â Â Â 424448 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\Kernel Base.dll
2013-08-02 01:59:30 Â Â Â Â Â 3968960 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\ntkrnl pa.exe
2013-08-02 01:59:30 Â Â Â Â Â 3913664 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\ntoskr nl.exe
2013-08-02 01:51:23 Â Â Â Â Â 1292192 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\ntdll. dll
2013-08-02 01:50:42 Â Â Â Â Â 5120 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\wow32. dll
2013-08-02 01:50:42 Â Â Â Â Â 274944 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\Kernel Base.dll
2013-08-02 01:09:17 Â Â Â Â Â 338432 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\conhos t.exe
2013-08-02 00:59:09 Â Â Â Â Â 112640 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\smss.e xe
2013-08-02 00:45:37 Â Â Â Â Â 25600 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\setup1 6.exe
2013-08-02 00:45:36 Â Â Â Â Â 14336 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\ntvdm6 4.dll
2013-08-02 00:45:35 Â Â Â Â Â 7680 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\instnm .exe
2013-08-02 00:45:34 Â Â Â Â Â 2048 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\user.e xe
2013-08-02 00:43:05 Â Â Â Â Â 6144 Â Â Â Â Â ---ha-w- Â Â Â Â Â C:\Windows\SysWow64\api-ms -win-secur ity-base-l 1-1-0.dll
2013-08-02 00:43:05 Â Â Â Â Â 4608 Â Â Â Â Â ---ha-w- Â Â Â Â Â C:\Windows\SysWow64\api-ms -win-core- threadpool -l1-1-0.dl l
2013-08-02 00:43:05 Â Â Â Â Â 3584 Â Â Â Â Â ---ha-w- Â Â Â Â Â C:\Windows\SysWow64\api-ms -win-core- xstate-l1- 1-0.dll
2013-08-02 00:43:05 Â Â Â Â Â 3072 Â Â Â Â Â ---ha-w- Â Â Â Â Â C:\Windows\SysWow64\api-ms -win-core- util-l1-1- 0.dll
2013-07-29 16:39:40 Â Â Â Â Â 96168 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\Window sAccessBri dge-32.dll
2013-07-29 16:39:37 Â Â Â Â Â 867240 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\npDepl oyJava1.dl l
2013-07-29 16:39:37 Â Â Â Â Â 789416 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\deploy Java1.dll
2013-07-25 09:25:54 Â Â Â Â Â 1888768 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\WMVDEC OD.DLL
2013-07-25 08:57:27 Â Â Â Â Â 1620992 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\WMVDEC OD.DLL
2013-07-19 01:58:42 Â Â Â Â Â 2048 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\tzres. dll
2013-07-19 01:41:01 Â Â Â Â Â 2048 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\tzres. dll
2013-07-09 05:52:52 Â Â Â Â Â 224256 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\wintru st.dll
2013-07-09 05:51:16 Â Â Â Â Â 1217024 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\rpcrt4 .dll
2013-07-09 05:46:20 Â Â Â Â Â 184320 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\crypts vc.dll
2013-07-09 05:46:20 Â Â Â Â Â 1472512 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\crypt3 2.dll
2013-07-09 05:46:20 Â Â Â Â Â 139776 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\cryptn et.dll
2013-07-09 04:52:33 Â Â Â Â Â 663552 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\rpcrt4 .dll
2013-07-09 04:52:10 Â Â Â Â Â 175104 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\wintru st.dll
2013-07-09 04:46:31 Â Â Â Â Â 140288 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\crypts vc.dll
2013-07-09 04:46:31 Â Â Â Â Â 1166848 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\crypt3 2.dll
2013-07-09 04:46:31 Â Â Â Â Â 103936 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\cryptn et.dll
2013-07-06 06:03:53 Â Â Â Â Â 1910208 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver s\tcpip.sy s
.
============= FINISH: 14:32:42.10 ===============
attach.zip
DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 10.0.9200.16686 Â BrowserJavaVersion: 10.25.2
Run by Owner at 14:25:53 on 2013-09-19
Microsoft Windows 7 Professional  6.1.7601.1.1252.1.1033.18.
.
AV: Microsoft Security Essentials Prerelease *Enabled/Updated* {641105E6-77ED-3F35-A304-7
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-D
SP: Microsoft Security Essentials Prerelease *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.ex
C:\Windows\system32\svchos
C:\Windows\system32\svchos
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchos
C:\Windows\system32\svchos
C:\Windows\system32\svchos
C:\Windows\system32\svchos
C:\Windows\system32\svchos
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon
C:\Windows\System32\svchos
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\system
C:\Windows\system32\taskmg
C:\Windows\system32\wbem\w
C:\Windows\System32\cscrip
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uURLSearchHooks: UrlSearchHook Class: {00000000-6E41-4FD3-8538-5
mWinlogon: Userinit = userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D
BHO: TidyNetwork.com: {7736C7FA-512D-11E2-B871-D
BHO: Define: {B78F92C8-DEB3-11E2-9A0A-F
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4
TB: Delta Toolbar: {82E1477C-B154-48D3-9891-3
mRun: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
mRun: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSy
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeA
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windo
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\OFFIC
IE: {92780B25-18CC-41C8-B9BE-3
DPF: {D27CDB6E-AE6D-11CF-96B8-4
TCP: NameServer = 10.0.0.2
TCP: Interfaces\{F1AAC217-E342-
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-8
Handler: qbwc - {FC598A64-626C-4447-85B8-5
AppInit_DLLs= c:\progra~3\bitguard\26167
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A
x64-Run: [picon] "C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PIconStartup.exe" -startup
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-8
x64-Handler: qbwc - {FC598A64-626C-4447-85B8-5
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Owner\AppData\Roa
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/
FF - prefs.js: browser.search.selectedEng
FF - prefs.js: browser.startup.homepage - hxxp://www2.delta-search.c
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dl
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin
FF - plugin: C:\Windows\SysWOW64\Macrom
FF - plugin: C:\Windows\SysWOW64\npDepl
FF - plugin: C:\Windows\SysWOW64\npmpro
FF - ExtSQL: 2013-09-03 00:00; umylsm@sqhjcpzmeselzlp.org
FF - ExtSQL: 2013-09-03 15:51; tidynetwork@tidynetwork; C:\Users\Owner\AppData\Roa
FF - ExtSQL: 2013-09-03 15:52; {650598e1-b35a-45d3-b607-8
FF - ExtSQL: 2013-09-11 15:49; ffxtlbr@delta.com; C:\Users\Owner\AppData\Roa
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.delta.tlbrSrchU
FF - user.js: extensions.delta.id - c02c4b1b0000000000000024e8
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0
FF - user.js: extensions.delta.instlDay - 15959
FF - user.js: extensions.delta.vrsn - 1.8.24.6
FF - user.js: extensions.delta.vrsni - 1.8.24.6
FF - user.js: extensions.delta.vrsnTs - 1.8.24.615:49:40
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlR
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrac
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\driv
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\Syste
S0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32
S2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32
S3 dmvsc;dmvsc;C:\Windows\Sys
S3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32
S3 MBAMProtector;MBAMProtecto
S3 TsUsbFlt;TsUsbFlt;C:\Windo
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32
.
=============== Created Last 30 ================
.
2013-09-19 17:50:24 Â Â Â Â Â 32512 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver
2013-09-18 22:35:44 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa
2013-09-18 22:35:16 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\Malwarebyte
2013-09-18 22:35:08 Â Â Â Â Â 25928 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver
2013-09-18 22:35:07 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-18 22:34:50 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc
2013-09-18 22:32:09 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Windows\pss
2013-09-18 21:21:17 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\HitmanPro
2013-09-18 17:18:50 Â Â Â Â Â 9694160 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\ProgramData\Microsoft\M
2013-09-16 17:22:12 Â Â Â Â Â 9694160 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\ProgramData\Microsoft\M
2013-09-14 23:34:24 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\BitGuard
2013-09-12 15:50:48 Â Â Â Â Â 155584 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver
2013-09-12 15:47:19 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc
2013-09-12 15:38:12 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\Systweak
2013-09-12 15:38:09 Â Â Â Â Â 16896 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\sasnat
2013-09-12 15:38:09 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\Advanced System Protector
2013-09-11 19:49:40 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa
2013-09-11 19:49:38 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\Delta
2013-09-11 19:49:37 Â Â Â Â Â 19368 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\roboot
2013-09-11 19:49:33 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa
2013-09-11 19:49:29 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\RegClean Pro
2013-09-11 19:49:02 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa
2013-09-11 19:49:02 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\DSearchLink
2013-09-11 19:48:46 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\ProgramData\Babylon
2013-09-07 18:13:45 Â Â Â Â Â 965008 Â Â Â Â Â ------w- Â Â Â Â Â C:\ProgramData\Microsoft\M
2013-09-03 19:52:11 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc
2013-09-03 19:52:10 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Roa
2013-09-03 19:52:08 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Program Files (x86)\AWS
2013-09-03 19:51:25 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc
2013-09-03 19:51:17 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â C:\Users\Owner\AppData\Loc
2013-08-28 20:35:00 Â Â Â Â Â 250352 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver
.
==================== Find3M Â ====================
.
2013-09-19 17:43:33 Â Â Â Â Â 71048 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\FlashP
2013-09-19 17:43:33 Â Â Â Â Â 692616 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\FlashP
2013-08-28 20:35:02 Â Â Â Â Â 139616 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver
2013-08-10 05:22:18 Â Â Â Â Â 2241024 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\winine
2013-08-10 05:20:59 Â Â Â Â Â 3959296 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\jscrip
2013-08-10 05:20:55 Â Â Â Â Â 67072 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\iesetu
2013-08-10 05:20:55 Â Â Â Â Â 136704 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\iesysp
2013-08-10 03:59:10 Â Â Â Â Â 1767936 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\winine
2013-08-10 03:58:09 Â Â Â Â Â 2876928 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\jscrip
2013-08-10 03:58:06 Â Â Â Â Â 61440 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\iesetu
2013-08-10 03:58:06 Â Â Â Â Â 109056 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\iesysp
2013-08-10 03:17:38 Â Â Â Â Â 2706432 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\mshtml
2013-08-10 03:07:50 Â Â Â Â Â 2706432 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\mshtml
2013-08-10 02:27:59 Â Â Â Â Â 89600 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\Regist
2013-08-10 02:17:19 Â Â Â Â Â 71680 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\Regist
2013-08-08 01:20:43 Â Â Â Â Â 3155456 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\win32k
2013-08-02 02:23:53 Â Â Â Â Â 5550528 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\ntoskr
2013-08-02 02:15:44 Â Â Â Â Â 1732032 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\ntdll.
2013-08-02 02:15:03 Â Â Â Â Â 362496 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\wow64w
2013-08-02 02:15:03 Â Â Â Â Â 243712 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\wow64.
2013-08-02 02:15:03 Â Â Â Â Â 13312 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\wow64c
2013-08-02 02:14:57 Â Â Â Â Â 215040 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\winsrv
2013-08-02 02:14:11 Â Â Â Â Â 16384 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\ntvdm6
2013-08-02 02:13:34 Â Â Â Â Â 424448 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\Kernel
2013-08-02 01:59:30 Â Â Â Â Â 3968960 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\ntkrnl
2013-08-02 01:59:30 Â Â Â Â Â 3913664 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\ntoskr
2013-08-02 01:51:23 Â Â Â Â Â 1292192 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\ntdll.
2013-08-02 01:50:42 Â Â Â Â Â 5120 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\wow32.
2013-08-02 01:50:42 Â Â Â Â Â 274944 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\Kernel
2013-08-02 01:09:17 Â Â Â Â Â 338432 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\conhos
2013-08-02 00:59:09 Â Â Â Â Â 112640 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\smss.e
2013-08-02 00:45:37 Â Â Â Â Â 25600 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\setup1
2013-08-02 00:45:36 Â Â Â Â Â 14336 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\ntvdm6
2013-08-02 00:45:35 Â Â Â Â Â 7680 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\instnm
2013-08-02 00:45:34 Â Â Â Â Â 2048 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\user.e
2013-08-02 00:43:05 Â Â Â Â Â 6144 Â Â Â Â Â ---ha-w- Â Â Â Â Â C:\Windows\SysWow64\api-ms
2013-08-02 00:43:05 Â Â Â Â Â 4608 Â Â Â Â Â ---ha-w- Â Â Â Â Â C:\Windows\SysWow64\api-ms
2013-08-02 00:43:05 Â Â Â Â Â 3584 Â Â Â Â Â ---ha-w- Â Â Â Â Â C:\Windows\SysWow64\api-ms
2013-08-02 00:43:05 Â Â Â Â Â 3072 Â Â Â Â Â ---ha-w- Â Â Â Â Â C:\Windows\SysWow64\api-ms
2013-07-29 16:39:40 Â Â Â Â Â 96168 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\Window
2013-07-29 16:39:37 Â Â Â Â Â 867240 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\npDepl
2013-07-29 16:39:37 Â Â Â Â Â 789416 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\deploy
2013-07-25 09:25:54 Â Â Â Â Â 1888768 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\WMVDEC
2013-07-25 08:57:27 Â Â Â Â Â 1620992 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\WMVDEC
2013-07-19 01:58:42 Â Â Â Â Â 2048 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\tzres.
2013-07-19 01:41:01 Â Â Â Â Â 2048 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\tzres.
2013-07-09 05:52:52 Â Â Â Â Â 224256 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\wintru
2013-07-09 05:51:16 Â Â Â Â Â 1217024 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\rpcrt4
2013-07-09 05:46:20 Â Â Â Â Â 184320 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\crypts
2013-07-09 05:46:20 Â Â Â Â Â 1472512 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\crypt3
2013-07-09 05:46:20 Â Â Â Â Â 139776 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\cryptn
2013-07-09 04:52:33 Â Â Â Â Â 663552 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\rpcrt4
2013-07-09 04:52:10 Â Â Â Â Â 175104 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\wintru
2013-07-09 04:46:31 Â Â Â Â Â 140288 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\crypts
2013-07-09 04:46:31 Â Â Â Â Â 1166848 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\crypt3
2013-07-09 04:46:31 Â Â Â Â Â 103936 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\SysWow64\cryptn
2013-07-06 06:03:53 Â Â Â Â Â 1910208 Â Â Â Â Â ----a-w- Â Â Â Â Â C:\Windows\System32\driver
.
============= FINISH: 14:32:42.10 ===============
attach.zip
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Just make sure that shortcuts of browsers doesn't have the links to any of these.
Sudeep
Sudeep
ASKER
Thank you for the tip. I'll check for that in a little bit.
ASKER